Information Disclosure Vulnerability in FreeRDP Before Version 3.31.0
CVE-2026-85089

7.1HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85089?

FreeRDP versions 3.0.0 through 3.30.0 are susceptible to an information disclosure vulnerability resulting from the transmission of uninitialized heap memory. This occurs specifically in the Save Session Info PDU reserved padding fields, where three PDU writers fail to properly zero out reserved pad bytes, potentially sending stale heap data that may contain sensitive information, such as cleartext credentials, to the receiving peer. Systems utilizing FreeRDP-based servers and the rdpUpdate::SaveSessionInfo function, along with the freerdp-proxy, are particularly vulnerable, allowing the disclosure of memory contents which can compromise user credentials and other sensitive data.

Affected Version(s)

FreeRDP 3.0.0 < 3.31.0

FreeRDP 3.31.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VladimirEliTokarev
.